CVE-2021-3979
—CVSS 3.1
6.5 medium
EPSS
<1%p45
Published
()
Modified
Description
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.
- Vendors
- redhatfedoraproject
- Products
- ceph storage, openshift container storage, openshift data foundation, openstack platform, ceph storage for ibm z systems, ceph storage for power, fedora
- Weakness
- CWE-327, CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.